logo

Sednit reloaded: Back in the trenches

ID: d19a1242-8203-53d8-b790-884a2f9792e7

STIX ID: report--d19a1242-8203-53d8-b790-884a2f9792e7

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2026-03-10

Date Updated: 2026-05-01

...
...

Since April 2024 ESET documents the reactivation of Sednit’s advanced implant development, showing a dual-implant espionage strategy using BeardShell (PowerShell-based C2 via Icedrive) and a heavily modified Covenant (cloud-backed .NET implant using Filen/pCloud/Koofr), alongside a SlimAgent keylogger derived from Xagent. The report links these tools to Sednit’s 2010-era code through unique obfuscation and implementation artifacts, provides IoCs and MITRE mappings, and notes active use against Ukrainian military targets including exploitation of CVE-2026-21509.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.